top of page

Africa’s Post-Quantum Readiness 2026: What We Found Across 54 Countries

  • Writer: Brian Couzens
    Brian Couzens
  • 3 days ago
  • 5 min read

SITG-Consulting went looking for something we expected to find.

A continent-wide assessment of Africa’s preparedness for the transition to post-quantum cryptography.

We could not find one.

So the SITG-Consulting team conducted one.

The result is Africa’s Post-Quantum Readiness 2026: A 54-Country Empirical Assessment, examining publicly verifiable evidence across every UN-recognised African sovereign state as at 3 August 2026.

The headline number is difficult to ignore.

46 of 54 countries did not produce publicly verifiable PQC-specific activity sufficient to clear even the assessment’s lowest evidence threshold.

That is 85.2%.

But interpreting that as “Africa is doing nothing about PQC” would be inaccurate.

The evidence tells a more complicated story.

Ethiopia and Rwanda demonstrate substantive official PQC-specific activity. Kenya and Tunisia show structured policy or research activity. Cameroon, Egypt, Morocco and South Africa show more limited but credible evidence.

What we did not identify anywhere was an African state demonstrating the complete national migration machinery required to meet the assessment’s highest classification.

That distinction matters.

Quantum research is not cryptographic migration.

Cybersecurity capability is not cryptographic migration.

A conference is not cryptographic migration.

And knowing that RSA and elliptic-curve cryptography will eventually need replacing tells a government remarkably little about where those algorithms are embedded across thousands of systems, certificates, applications, HSMs, identities, devices and supplier relationships.


The problem is not awareness. It is migration.

PQC migration requires visibility over the existing cryptographic estate.

Governments need to know what cryptography they have, where it resides, what it protects, how long that protection must remain secure, who owns it and what depends upon it.

From there come the difficult parts: cryptographic inventories, prioritisation, crypto-agility, procurement requirements, supplier obligations, implementation roadmaps, testing, budgets and deadlines.

Our assessment found isolated signs that this transition has started.

What remains largely absent from the public record is the machinery required to execute it at national scale.

That becomes particularly clear when Africa is compared with jurisdictions where PQC has moved beyond awareness.

The United States now has federal cryptographic inventory and migration requirements with transition deadlines extending through 2030 and 2031.

The United Kingdom has established staged milestones through 2028, 2031 and 2035.

Canada has published a federal roadmap extending to 2035.

Australia is working towards an end-2030 transition horizon, supported by intermediate planning and critical-system milestones.

These jurisdictions have not “finished” PQC migration.

The difference is that they have begun building the machinery to execute it.

Across Africa, that machinery remains difficult to find.


Africa does not need 54 quantum computers

One misconception needs removing immediately.

African governments do not need domestic quantum computers before beginning PQC migration.

Post-quantum cryptography runs on conventional computing infrastructure.

The first requirement is far less glamorous.

Visibility.

Where is RSA deployed?

Where is elliptic-curve cryptography deployed?

Which certificates have long lifetimes?

Which HSMs require replacement or firmware upgrades?

Which government PKIs need transition?

Which payment systems depend on vulnerable public-key mechanisms?

Which firmware and code-signing systems rely on vulnerable digital signatures?

Which suppliers can support the new algorithms?

And who owns the migration?

A government that cannot answer those questions cannot realistically estimate the cost, complexity or duration of its transition.

Waiting for a cryptographically relevant quantum computer before asking them would be far too late.


This does not stop at Africa’s borders

There is another reason this assessment matters.

This is not solely an African cybersecurity problem.

Cryptographic trust crosses borders.

Banks depend on correspondent banks.

Telecommunications networks interconnect.

Cloud providers depend on customer infrastructure.

Multinationals depend on suppliers.

Governments depend on identity systems, certificate authorities, software vendors and technology manufactured elsewhere.

One organisation can migrate its cryptography.

One country can migrate its cryptography.

Neither can guarantee that every external party upon which it depends has done the same.

That creates a potential international dependency problem.

A European bank may complete its own PQC transition while continuing to exchange sensitive information with African correspondent institutions.

A multinational may migrate its internal systems while suppliers continue to use legacy certificates and signing mechanisms.

A cloud provider may deploy PQC capability while customer applications remain dependent upon cryptography that international standards and procurement requirements are beginning to retire.

The rest of the world cannot simply migrate around an entire continent.


A new cryptographic digital divide?

This raises a question that deserves considerably more attention.

Could uneven PQC migration create a new form of digital divide?

Not between countries that possess quantum computers and those that do not.

Between countries and infrastructures that have migrated their cryptographic trust and those still dependent upon mechanisms their international partners, suppliers and regulators are retiring.

If that divide emerges, the consequences could extend beyond cybersecurity.

Procurement requirements could change.

Supplier eligibility could change.

Cross-border interoperability could become more difficult.

Regulators could begin demanding evidence of cryptographic transition from organisations handling sensitive or long-lived information.

Financial institutions could face pressure from international counterparties.

And organisations that begin late may discover that migration is no longer occurring on their timetable.

None of those outcomes is inevitable.

But neither are they theoretical enough to ignore.


What the 54-country assessment actually found

The final classification was stark:

Tier 1 — National PQC Migration Programme: 0 countries

Tier 2 — Active National PQC Development: 2 countries

Tier 3 — PQC Research & Structured Awareness: 2 countries

Tier 4 — Limited PQC Evidence: 4 countries

Tier 5 — No Public PQC Evidence Identified: 46 countries

The Tier 5 classification requires particular care.

It does not mean nothing is happening inside those 46 countries.

It means our research did not identify credible, publicly verifiable PQC-specific activity sufficient to clear the assessment’s evidence threshold.

That distinction is deliberate.

Absence of public evidence is not proof of absence.

But when cryptographic migration requires coordination across government, regulators, procurement, suppliers and critical infrastructure, an absence of visible migration governance is itself significant.


This assessment is supposed to become outdated

The report is deliberately dated 3 August 2026.

PQC policy is moving too quickly for any assessment of this kind to pretend permanence.

We expect classifications to change.

We want them to change.

If a government, regulator, researcher or institution can provide primary evidence of PQC activity that the SITG-Consulting team has not identified, we want to see it.

Where the evidence changes, the classification should change.

The objective is not to defend a league table.

It is to establish a defensible baseline against which progress can be measured.

Africa’s post-quantum transition has begun.

The migration largely has not.

And given how deeply African financial systems, telecommunications networks, supply chains, cloud infrastructure, identity systems and trade relationships are connected to the rest of the world, that is not a problem the rest of the world can afford to regard as somebody else’s.

The full SITG-Consulting 23-page empirical assessment, including the methodology, all 54 country classifications, regional findings, international comparisons and source base, is permanently archived on Zenodo under CC BY 4.0.


DOI: 10.5281/zenodo.21770201

 
 
 
bottom of page